← Browse

CVE-2026-19321

Low

No strong exploitation signal.

CVSS base
6.7 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H
EPSS — probability of exploitation (30 days)
0.1%
1.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-190
Published 2026-08-19 · modified 2026-08-25

CVSS breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H

Attack VectorLLocal
Attack ComplexityLLow
Privileges RequiredHHigh
User InteractionNNone
ScopeCChanged
ConfidentialityLLow
IntegrityNNone
AvailabilityHHigh

Timeline

Description

Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access to the service processor can supply a carefully crafted command that could leak the contents of hardware registers that should be inaccessible to the service processor. Successful exploitation could result in limited confidentiality or availability impacts to the affected host system.

Affected

ibm

References

Official: NVD · CVE.org